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IN THE CLAIMS: 

Please amend the claims as follows: 

1 . (Currently amended) A computer program stored on a computer readable 
hardware storage medium for identifying malicious portions in a suspect computer program 
comprising: 

a preprocessor portion for receiving the suspect computer program in executable 
form and creating a logically equivalent standardized version also in executable form o f 
the suspect program without executing the suspect progra m, the logical equivalent 
standardized version if executed providing an equivalent result as execution of the 
suspect computer program : 

a library of standardized malicious code portions; and 
a detector portion reviewing the standardized version against the library of 
malicious code portions to provide an output indicating when a malicious code portion is 
present in the suspect program. 

2. (Original) The computer program of claim 1 wherein the standardized version 

identifies the execution order of instructions of the suspect program and wherein the detector 
portion reviews the instructions of the standardized version according to the execution order. 

3. (Original) The computer program of claim 2 wherein the preprocessor identifies 
the execution order of the instructions by generation of a control-flow Usting of the instructions. 

4. (Original) The computer program of claim 1 wherein the standardized version 
maps instructions of the suspect program to corresponding standard synonym instructions. 

5. (Original) The computer program of claim 4 wherein the standard synonym 
instructions are different in number from the instructions of the suspect program to which the 
synonym instructions map. 
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6. (Original) The computer program of claim 1 wherein the standardized version 
removes irrelevant portions of the suspect program. 

7. (Original) The computer program of claim 6 wherein the preprocessor removes 
irrelevant portions by identifying irrelevant portions to the detector so that the detector ignores 
identified irrelevant portions when reviewing the standardized version. 

8. (Original) The computer program of claim 1 wherein the irrelevant portions are 
one or more nop instructions. 

9. (Original) The computer program of claim 1 wherein the standardized version 
uses uninterpreted variables. 

1 0. (Original) The computer program of claim 1 wherein the suspect program is a 
binary executable and wherein the preprocessor receives the binary executable to generate a 
Usting of instructions and data values. 

11. (Canceled) 

12. (Currently amended) A computer program stored on a computer readable 
hardware storage medium for identifying mahcious portions in a suspect computer program 
comprising: 

a preprocessor portion for receiving the suspect computer program and creating a 
logically equivalent standardized version of the suspect program without executing the suspect 
program: 

a library of standardized malicious code portions: and 

a detector portion reviewing the standardized version against the library of malicious 
code portions to provide an output indicating when a malicious code portion is present in the 
suspect program: 
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the computer program further including a library of patterns matching to one or more 
instructions of the suspect program and wherein the preprocessor creates the standardized 
version by replacing instructions of the suspect program with matching ones of the library of 
patterns and wherein the library of standardized malicious code portions are also collections of 
ones of the library of patterns Th e computer program of claim 1 1 wherein a pattern is at least one 
instruction logically replacing at least one different instruction in the suspect program. 

1 3 . (Currently amended) A computer program stored on a computer readable 
hardware storage medium for identifying malicious portions in a suspect computer program 
comprising: 

a preprocessor portion for receiving the suspect computer program and creating a 
logically equivalent standardized version of the suspect program without executing the 
suspect program: 

a library of standardized malicious code portions: and 
a detector portion reviewing the standardized version against the library of malicious 
code portions to provide an output indicating when a malicious code portion is present in the 
suspect program; 

the computer program further including a library of patterns matching to one or more 
instructions of the suspect program and wherein the preprocessor creates the standardized 
version by replacing instructions of the suspect program with matching ones of the library of 
patterns and wherein the library of standardized malicious code portions are also collections of 
ones of the library of patterns The comput e r program of claim 1 1 wherein a pattern ih is a tag 
replacing at least one instruction logically having no substantive effect on the execution of the 
suspect program; and wherein the a library of patterns is implemented as a look-up table 
matching instructions to the patterns. 

14. (Original) The computer program of claim 1 wherein the library of standardized 
malicious code provides instructions of the malicious code identified as to execution order. 
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15. (Original) The computer program of claim 1 wherein the library of standardized 
malicious code expresses instructions of the malicious code as standard synonym instructions. 

1 6. (Original) The computer program of claim 1 wherein the Ubrary of standardized 
malicious code wherein the standardized version removes irrelevant program portions from the 
mahcious code. 

17. (Original) The computer program of claim 1 wherein the detector portion outputs 
a representation of the malicious portion when a malicious portion is present in the suspect 
program. 
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